Lucene search

K
cvePatchstackCVE-2023-51524
HistoryJun 12, 2024 - 10:15 a.m.

CVE-2023-51524

2024-06-1210:15:28
CWE-862
Patchstack
web.nvd.nist.gov
46
cve-2023-51524
reserved
potential
security
issue
announcement
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

19.7%

Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.18.

Affected configurations

Nvd
Vulners
Vulnrichment
Node
weformsproweformsRange<1.6.19wordpress
VendorProductVersionCPE
weformsproweforms*cpe:2.3:a:weformspro:weforms:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "weforms",
    "product": "weForms",
    "vendor": "weForms",
    "versions": [
      {
        "changes": [
          {
            "at": "1.6.19",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "1.6.18",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

19.7%